Here's what I have: I'm using a payment gateway for my website and so I provide my own credit card details form and send data to the back end through XML. Should I need to worry about PCI compliance? As long as my website is on SSL, I don't have to worry right? Thanks!

We are doing our PCI compliance scans and our Windows Server 2008 R2 was hit by a Nessus Plugin ID. Should I be worried? It has DDoS in the title so that scares me. Here's what it says: Plugin ID: 35450 Name: DNS Server Spoofed Request Amplification DDoS Synopsis: The remote DNS server could be...

I know nothing about computers. Not sure how I got here and signed in? I have two desktops, two tablets and two smartphones. Also just received my new laptop today. Besides the new one not yet touched each of my computers are either barely functioning, hacked or too full of nonsense to function at...

We did a PCI scan for one of our clients and it says they failed due to the SSL certificate, for SMTP Port 25, not matching the domain scanned. Here's what it said: Description: SSL Certificate with Wrong Hostname Synoposis: The SSL certificate for this service is for a different host. Impact: The...

I have to deploy some file integrity monitoring / intrusion detection software on our AWS instances. We wanted to use OSSEC but we realized it doesn't work well in our environment (our servers auto deploy and shut down based on load). What should we use that covers PCI DSS on AWS (hopefully it's...

For PCI DSS requirements, if a session is idle for more than 15 minutes, the user will have to re-authenticate to re-activate the terminal or session. So, because of this, we had to deal with SSH sessions that are idling at the bash prompt by enforcing a global $TMOUT of 900. But we realized that...

Recently, I've been looking to use Authorize.NET (CIM and DPM solutions). However, we can't reference a CIM profile in the DPM. Basically, I need to become PCI compliant because this handles credit cards. Here's my question: Is there something similar to Authorize.NET that allows our site to never...

We have a Fedora server that's running on Apache to pass a PCI DSS compliance scan by McAfee. Here's what we used for the default SSLCipherSuite and SSLProtocol. SSLProtocol ALL -SSLv2 SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP So it failed because of weak ciphers. We changed it...

We are migrating users from one exchange server to another. the users sit in remote sites and use very slow links to connect to the exchange server. Is it possible to use the old ost on the pc for the new exchange server instead of recreating the ost with the new exchange server, which can take...

Due to PCI compliance, we have to disable plaintext authentication. We were able to do this through encapsulating communications between our mail server and clients with TLS on port 465. Here's where the problem is: Port 25 has to remain open / unencrypted for us to receive mail, but it shouldn't...

I've been working on our PCI DSS assessment. I already know that passwords must be changed every 90 days / different than previous passwords. But I'm not sure if this is for access to the server or to the app we provide to users on the server. If it's the second part, can we enforce this in ASP.NET...

We're working on a website that would allow our users to pay with their credit cards. We're outside of the country so we can't use a normal merchant account (like Braintree). Does anyone happen to know of a credit card service that would allow us to store credit card info and access them through an...

From what I understand, storing a shipping address would be okay for PCI compliance right? Do configuration standards include requirements for a firewall at each Internet connection? Is there a process for approving and testing all external network connections? I'm leaning towards no but I need to...

To follow this tag...

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States.
Privacy